If you are a UK company, you must still comply with the GDPR (General Data Protection Regulation) in certain circumstances, even after Brexit. This post explains when UK businesses must follow GDPR rules and highlights the critical aspects of the UK’s data protection landscape.

UK GDPR post-Brexit

Following Brexit, the UK adopted its own data protection legislation called the UK General Data Protection Regulation (UK GDPR). UK GDPR aligns closely with the EU version (for now), and UK companies processing personal data within the UK must comply with it. The Information Commissioner’s Office enforces the UK GDPR.

UK and EU GDPR have similarities, but understanding the differences is vital for UK businesses operating at home and abroad.

EU GDPR compliance

Your organisation need to follow the EU GDPR if you:

  • Offer goods or services to people in the EU; or
  • Monitor the people’s behaviour in the EU.

Even without a physical presence in the EU, as a UK company, you may still need to comply with the EU GDPR if you process the personal data of data subjects in the EU under the circumstances we mention above.

For example, A UK-based online retailer could sell clothing and accessories to customers in the EU. Because it offers goods to EU individuals, the retailer must comply with the EU GDPR. Another example is a UK-based analytics company that could track users’ online browsing habits in the EU to provide targeted advertising services. Despite not having a physical presence in the EU, the company must adhere to the EU GDPR as it monitors the behaviour of individuals within the EU.

Post-Brexit compliance

UK companies must comply with the GDPR (both EU and UK versions) depending on the scope of their activities and the location of the data subjects whose personal data they process. To ensure compliance, businesses should:

  • Understand the differences and similarities between the EU GDPR and the UK GDPR.
  • Determine whether their activities require compliance with the EU GDPR, UK GDPR, or both.
  • Implement data protection measures in line with the relevant GDPR requirements.
  • Stay updated on any changes in data protection regulations and guidelines.

UK companies must comply with GDPR rules in various circumstances, even after leaving the European Union. By understanding the requirements of both the EU GDPR and the UK GDPR, you can ensure, as a UK business, you meet your data protection obligations and safeguard the privacy of your data subjects in the digital age.

Actions you can take

  • Contact us about how we can help you to comply with the UK GDPR and the EU GDPR. 
  • Join our data protection programme to help you keep up to date with EU data protection regulations and guidelines.
  • Contact us for an assessment to determine if your processing activities need to comply with the UK GDPR, EU GDPR, or both.Â